
bvandeusenandClaude Sonnet 4.6
00643c778e
security: fix 10 vulnerabilities from security audit
- SSRF: block private/internal URLs in image cache fetch
- SSRF: block private/internal URLs in RSS feed fetch (scheme guard)
- SSRF: block private/internal URLs in CalDAV URL setting
- Auth: require login for GET /api/images/<id> (was unauthenticated)
- Auth: restrict Ollama model pull/delete to admin users only
- Info disclosure: remove email from /api/users/search response
- OAuth: skip email-based account linking when email_verified is false
- Config: raise hard error on default SECRET_KEY when SECURE_COOKIES=true
- Rate limit: document proxy header requirement; add startup warning
- XSS: remove src/alt from global DOMPurify ADD_ATTR allowlist
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-29 00:37:13 -04:00
..
2026-03-09 22:12:20 -04:00
2026-03-29 00:37:13 -04:00
2026-03-09 21:30:55 -04:00
2026-03-02 20:52:21 -05:00
2026-03-25 13:38:09 -04:00
2026-03-25 13:38:09 -04:00
2026-02-09 23:35:44 -05:00
2026-02-09 23:35:44 -05:00
2026-02-09 23:35:44 -05:00